Skip to content

Releases: OpenCTI-Platform/connectors

Version 7.260817.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 17 Aug 17:54
1e2cbcb

Enhancements:

  • #7258 feat(connectors-sdk): add CourseOfAction and CaseIncident models
  • #7256 feat(connectors-sdk): add labels field to Infrastructure model
  • #6820 feat(threat-landscape): add external import connector
  • #6595 feat(dark-web-informer): create the external import connector
  • #6070 feat(connectors-sdk): add aliases and labels fields to OCTI models when missing

Bug Fixes:

  • #7270 fix(greynoise-feed): uncaught ValueError when parsing last_seen with unexpected date format
  • #7267 fix(zscaler): remove unused OpenCTIApiClient initialization causing startup crash
  • #7264 fix(servicenow): connector crashes instantly when deployed via composer due to unhandled int(None) in get_config_variable
  • #7261 fix(misp): TypeError 'ObjectItemObjectReference' object is not subscriptable in process_events
  • #6948 fix(thehive): crashes on startup with import_from_date, on empty runs, and on TheHive 4 comment/attachment fetches
  • #6677 fix(import-document): IPv4 addresses extracted as Phone-Number observables by import-document connector

Community Contributions Highlight:


Pull Requests:

New Contributors:

Full Changelog: 7.260811.0...7.260817.0

Version 7.260309.0-lts.7

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 14 Aug 15:15
ac2d3b8

Version 7.260811.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 11 Aug 15:55
264d13d

Enhancements:

  • #7149 feat(connector-domaintools-iris-detect): new connector
  • #6911 feat(ransomwarelive): support ransomware.live API-PRO (configurable base URL + API key)
  • #6829 feat(modat-enrichment): create the connector
  • #6703 feat(connectors): add Lab539 AiTM Feed external import connector

Bug Fixes:

  • #7207 fix(modat-enrichment): fix connector metadata
  • #7205 fix(lab539-aitm-feed): fix connector metadata
  • #7198 fix(infoblox): connector crash
  • #7181 fix(import-ttps-file-navigator): contextual import fails with error 'AppLogger' object is not callable

Pull Requests:

New Contributors:

Full Changelog: 7.260807.0...7.260811.0

Version 7.260807.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 07 Aug 12:48
522f6ac

Enhancements:

  • #7063 feat(stream-microsoft-sentinel-intel): Add native azure auth
  • #7043 feat(cloudflare): add Cloudflare Rules List stream connector
  • #7042 feat(metras): Add Metras EDR connector suite (external-import, internal-enrichment, stream)
  • #7036 feat(email-cases-importer): add connector to import emails as incident-response cases

Bug Fixes:

  • #7157 fix: ModuleNotFoundError: No module named 'magic' for connectors importing magic

Pull Requests:

  • chore(deps): update dependency cryptography to v50 [security] by renovate[bot] in #7160
  • feat(stream-microsoft-sentinel-intel): add native azure auth (#7063) by Renizmy in #7064
  • feat(email-cases-importer): add connector to import emails as incident-response cases (#7036) by Khidr6G in #7037
  • feat(metras): add Metras external-import connector for EDR telemetry (#7042) by Khidr6G in #7039
  • feat(metras): add Metras internal-enrichment connector for fleet-presence lookups (#7042) by Khidr6G in #7040
  • feat(metras): add Metras stream connector for blocklist sync (#7042) by Khidr6G in #7041
  • test(all): update connector_config_schema.json tests (#6342) by Pauline Eustachy (@Powlinett) in #7146
  • feat(cloudflare-rules-list): add Cloudflare Rules List stream connector (#7043) by Khidr6G in #7044

Full Changelog: 7.260803.0...7.260807.0

Version 7.260803.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 04 Aug 08:54
2f80c4a

Enhancements:

  • #7128 feat(domaintools-feeds): create external-import connector
  • #7127 feat(domaintools-irisql): create external-import connector
  • #7124 feat(vulners): send an identifying User-Agent to the Vulners API
  • #7114 refactor(socradar): migrate connector to be connector manager supported
  • #6940 feat(MalwareBazaar): Add external references to indicators linking to MalwareBazaar
  • #6868 feat(ThreatMatch): migrate connector to the catalog
  • #5256 refactor(sumologic-intel): migrate connector to be connector manager supported
  • #2044 feat(malwarebazaar): improve the connector

Bug Fixes:

  • #7154 fix(external-import/opencti): align UBI9 CONNECTOR_CMD with actual entrypoint
  • #7152 fix(import-file-stix): PermissionError on /.stixmarx at startup for non-root/arbitrary-UID deployments
  • #7144 fix(converter): invalid indicator value and add API metadata
  • #7138 fix(google-ti-feeds): indicator/observable score defaults to 50 for benign IOCs with a real score of 0
  • #7100 fix(connectors-sdk): BaseSettings serialization and security issues
  • #7025 fix(Doppel): URLs are being ingested as Domain Names

Pull Requests:

New Contributors:

Full Changelog: 7.260728.0...7.260803.0

Version 7.260728.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 28 Jul 16:34
0f44b31

Enhancements:

  • #7105 feat(spur): create external-import connector
  • #7075 feat(decoupling): manifest fragments improvements and misc fixes
  • #7057 feat(crowdstrike-recon): add UBI9 image build support
  • #7053 feat(google-ti-feeds): parametrize sub-entities to fetch per data collection
  • #7033 feat(doppel-alert-takedown): add Doppel Alert and Takedown internal enrichment connector
  • #7024 feat(google-ti-feeds): add malware/threat actor association filters for Delta Sync indicator import
  • #6989 feat(ransomlook): create the connector
  • #6946 feat(manifest): add "License Type" metadata to characterize connector's associated feed/solution license
  • #6865 feat(Zscaler): migrate connector to the catalog
  • #6863 feat(ZeroFox): migrate connector to the catalog
  • #6862 feat(ServiceNow): migrate connector to the catalog
  • #6861 feat(SOC Prime): migrate connector to the catalog
  • #6860 feat(Shodan InternetDB): migrate connector to the catalog
  • #6855 feat(google-ti-feeds): Add minimum GTI score filter for Delta Sync indicator import
  • #6853 feat(MalBeacon): migrate connector to the catalog
  • #6771 feat(Import File STIX): migrate connector to the catalog

Bug Fixes:

  • #7070 fix(taxii-post): empty token env var prevents basic auth fallback
  • #6555 fix(urlscan): ignores some user configs
  • #4756 fix(hatching-triage): unable to enrich URL

Pull Requests:

New Contributors:

Full Changelog: 7.260722.0...7.260728.0

Version 7.260722.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 22 Jul 13:17
3bf37ed

Enhancements:

  • #6983 feat(ioc-extractor): upgrade connector to verified status
  • #6936 feat(decoupling): chunk 6 bulk release tool
  • #6928 feat(manifest): introduce "solution_categories" field to classify connectors by solution type
  • #6867 feat(TweetFeed): migrate connector to the catalog
  • #6864 feat(Zvelo): migrate connector to the catalog
  • #6857 feat(Splunk): migrate connector to the catalog
  • #6856 feat(TeamT5): migrate connector to the catalog
  • #6854 feat(Atlassian Jira): migrate connector to the catalog
  • #6852 feat(Maltiverse): migrate connector to the catalog
  • #6851 feat(Malcore): migrate connector to the catalog
  • #6849 feat(RST Report Hub): migrate connector to the catalog
  • #6848 feat(RST Threat Feed): migrate connector to the catalog
  • #6847 feat(Cofense ThreatHQ): migrate connector to the catalog
  • #6846 feat(Citalid): migrate connector to the catalog
  • #6844 feat(Greynoise): migrate connector to the catalog
  • #6662 feat(zerofox-alerts): new integration for Zero Fox Alerts

Bug Fixes:

  • #7045 fix(misp): error with attribute filter
  • #7031 fix(opencti-stream): STIX bundle created with applicant_id: null
  • #6912 fix(Intel 471v2): TypeError init unexpected keyword arg 'proxy'
  • #6813 fix(sekoia): no timeouts for http requests

Pull Requests:

Full Changelog: 7.260715.0...7.260722.0

Version 7.260715.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 15 Jul 19:14
df5a941

Enhancements:

  • #6970 feat(vulners): add Vulners enrichment connector
  • #6967 feat(microsoft-sentinel-intel): publish author as STIX Identity
  • #6866 feat(Urlscan.io): migrate connector to the catalog
  • #6841 feat(Infoblox): migrate connector to the catalog
  • #6707 feat(connectors): add Whisper internal-enrichment connector for infrastructure graph
  • #2945 feat(google-secops-soar): develop the integration

Bug Fixes:

  • #7002 fix(microsoft-defender-intel): connector crashes on every event with TypeError, HttpUrl + str, during OAuth token acquisition (regression in 7.260520.0)
  • #6915 fix(cve): proxy support
  • #6670 fix(thehive): case TLP filter bypassed and latent crashes in bundle generation

Pull Requests:

New Contributors:

Full Changelog: 7.260710.0...7.260715.0

Version 7.260710.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 10 Jul 13:26
b74db91

Enhancements:

  • #6973 feat(sdk): add x_opencti_cwe field to SDK Vulnerability model
  • #6956 feat(sekoia): Opt remove confidence from bundle
  • #6893 feat(ioc-extractor): new internal enrichment connector to extract IOCs from entity descriptions
  • #6843 feat(Hatching Triage Sandbox): migrate connector to the catalog
  • #6842 feat(IBM X-Force): migrate connector to the catalog
  • #6840 feat(IPsum): migrate connector to the catalog
  • #6838 feat(Elastic Security Incidents): migrate connector to the catalog
  • #6837 feat(ReversingLabs Malware Presence): migrate connector to the catalog
  • #6836 feat(ReversingLabs Spectra Intel Submission): migrate connector to the catalog
  • #6766 feat(Tenable Vulnerability Management): migrate connector to the catalog
  • #6524 feat(connectors-sdk): create BaseClientAPI
  • #6432 feat(datadog-intel): create stream connector forwarding indicators to Datadog Threat Intel
  • #6083 feat(vulnerability-lookup): create the connector
  • #5793 feat(google-ti): support fetching and modeling indicators associated with campaigns
  • #5412 feat(crowdstrike-recon): create EXTERNAL_IMPORT connector to bring CrowdStrike Recon notifications as Incidents into OpenCTI
  • #5215 refactor(tenable-vuln-management): migrate connector to be connector manager supported

Bug Fixes:

  • #6961 fix(swimlane): invalid scope configuration
  • #6960 fix(ctm360-threatcover): Invalid 'scope' configuration
  • #6959 fix(argsight-incidents): invalid scope configuration
  • #6941 feat(xtm-hub): fix connector manifest description syntax and normalize use_cases
  • #6938 fix(import-document): single document takes hours to process, stalling ingestion
  • #6934 fix(ci): unused-deps workflow scans connectors outside PR scope
  • #6932 fix: add correct logo to Flare connector
  • #6922 fix(MISP): MISP attribute level filtering errors
  • #6611 fix(feedly): memory leak causing OOM events
  • #6372 fix(tenable-security-center): validation error when asset_exposure_score is an empty string

Pull Requests:

New Contributors:

Full Changelog: 7.260706.0...7.260710.0

Version 7.260309.0-lts.6

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 09 Jul 11:44
d3c8fb2

Pull Requests:

Full Changelog: 7.260309.0-lts.5...7.260309.0-lts.6